← Back to ReRoll
Privacy Policy
Last updated: March 24, 2026
ReRoll ("we", "us", "our") is a media discovery app operated by CloudTaken (Houari Tadjer). This privacy policy explains how we collect, use, and protect your personal data when you use ReRoll at reroll.cloudtaken.com and our mobile applications. ReRoll helps you discover games, movies, TV shows, and books.
1. Data Controller
CloudTaken (Houari Tadjer)
Contact: skullkid785@gmail.com
2. Data We Collect
We collect the following data, which is necessary to provide the ReRoll service:
- Account information — email address and password, processed through Supabase Auth for account creation and login.
- Media library data — games, movies, TV shows, and books you save, your wishlist, ratings, and swipe preferences. This is core to providing personalised recommendations.
- Steam library sync — if you choose to connect your Steam account, we import your game library via the Steam Web API. This is optional and user-initiated.
- Social features — friend codes and connections you create within ReRoll.
- Push notification tokens — device tokens for sending push notifications on iOS and Android (mobile app only).
- Basic analytics — screen views, swipe events, and crash reports collected via Firebase Analytics on our mobile apps only.
3. Data We Do Not Collect
- Location data
- Payment or financial information (ReRoll is free with no in-app purchases)
- Advertising identifiers or ad tracking data
- We do not share your data with third parties for marketing or advertising purposes
4. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract performance — processing your account and game data is necessary to provide the ReRoll service (Art. 6(1)(b) GDPR).
- Consent — optional features like Steam library sync and push notifications are only activated with your explicit consent (Art. 6(1)(a) GDPR).
- Legitimate interest — basic analytics to improve app stability and user experience (Art. 6(1)(f) GDPR).
5. Third-Party Services
We use the following third-party services to operate ReRoll:
- Supabase — database and authentication, hosted in the EU.
- Vercel — web application hosting.
- Firebase (Google) — push notifications, analytics, and crash reporting (mobile apps only).
- IGDB / Twitch API — game metadata (titles, covers, descriptions). No user data is sent to IGDB.
- TMDB — movie and TV show metadata. No user data is sent to TMDB. This product uses the TMDB API but is not endorsed or certified by TMDB.
- Open Library — book metadata. No user data is sent to Open Library.
- Steam Web API — used only when you choose to sync your Steam library.
- Cloudflare Turnstile — captcha service for bot protection during sign-up and sign-in. Processes IP address and browser signals. No tracking cookies.
Each service processes data according to their own privacy policies. We encourage you to review them.
6. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, all associated data (profile, media library, ratings, social connections) will be permanently deleted within 30 days.
Analytics data collected via Firebase is retained for up to 14 months, in line with Firebase's default retention settings.
7. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate data.
- Right to erasure — request deletion of your account and all associated data.
- Right to restriction — ask us to restrict processing of your data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest.
- Right to withdraw consent — withdraw consent at any time for optional features (e.g., Steam sync, push notifications).
To exercise any of these rights, contact us at skullkid785@gmail.com. We will respond within 30 days.
8. Data Security
We take reasonable measures to protect your data:
- All connections use HTTPS/TLS encryption in transit.
- Passwords are hashed and never stored in plaintext (handled by Supabase Auth).
- Database access is restricted through row-level security policies.
- Our primary database is hosted in the EU (Supabase).
9. International Data Transfers
Your data is primarily stored in the EU via Supabase. Some data may be processed by Vercel (global CDN) and Firebase (Google Cloud). These transfers are covered by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR.
10. Children's Privacy
ReRoll is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Cookies
The ReRoll web app uses essential cookies and local storage for authentication and session management. We do not use advertising or tracking cookies. Firebase Analytics on mobile uses device identifiers, not cookies.
12. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. For significant changes, we will notify users via email or in-app notification.
13. Contact
If you have questions about this privacy policy or how we handle your data, contact us:
CloudTaken (Houari Tadjer)
Email: skullkid785@gmail.com
You also have the right to lodge a complaint with your local data protection authority.